cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
836
Views
0
Helpful
5
Replies

IPSEC Site-to-Site VPN: multiple crypto maps for one peer

Bjorntimmer
Level 1
Level 1

With à customer we have à site to site VPN connection. In this tunnel there is one subnet routed with a 3des-sha encryption / hash. Now the want to add a new subnet in this tunnel, but with a AES-128 / MD5 encryption / hash. Is it correct if we make a new crypto map with a higher seq. number?

Sent from Cisco Technical Support iPad App

1 Accepted Solution

Accepted Solutions

No problem, so you would want to modify your transform set then to include aes and modify your crypto acl to include the new network, and of course make sure both sides of the tunnel have the same crypto and ipsec settings.

View solution in original post

5 Replies 5

WILLIAM STEGMAN
Level 4
Level 4

If you add a new crypto map with a higher sequence #, that will only affect the phase 1 portion of the tunnel creation.  If you want to use aes on the IPSec tunnel itself, you'd want to modify the transform set being used as well.  However, I'm not entirely clear on what you're looking to do.  Do you want to add a second subnet to your crypto map and existing tunnel, or are you trying to create a 2nd tunnel to the same endpoint with different encryption standards for some reason?

I want to add a second subnet to the existing tunnel, but the customer wants to use a different encryption method on phase 2. Sorry for my knowledge. I'm just new to networking.

Sent from Cisco Technical Support iPad App

No problem, so you would want to modify your transform set then to include aes and modify your crypto acl to include the new network, and of course make sure both sides of the tunnel have the same crypto and ipsec settings.

Thanks, this was the right solution. It's all working fine now.

Sent from Cisco Technical Support iPad App

Bjorntimmer
Level 1
Level 1

Thank you. Tomorrow I need to do the change and I think it will be successful.

Sent from Cisco Technical Support iPhone App

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: